SB2016012014 - Input validation error in bind (Alpine package)
Published: January 20, 2016
Security Bulletin ID
SB2016012014
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2015-8705)
The vulnerability allows a remote non-authenticated attacker to #BASIC_IMPACT#.
buffer.c in named in ISC BIND 9.10.x before 9.10.3-P3, when debug logging is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit, or daemon crash) or possibly have unspecified other impact via (1) OPT data or (2) an ECS option.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=b527cfa00a7793b4db08311ff32263dce31eeae7
- https://git.alpinelinux.org/aports/commit/?id=1cff01908c342a676deca5a1d7261020c6241d2d
- https://git.alpinelinux.org/aports/commit/?id=efcb126bc36e67ceb010f9ca31daf5427d06efef
- https://git.alpinelinux.org/aports/commit/?id=dff85e5b601949d4052c57624e404e5788eec9d0
- https://git.alpinelinux.org/aports/commit/?id=a4e3789df52208f238990273e87a14b5556b9f69